{"id":2454,"date":"2026-10-05T17:08:03","date_gmt":"2026-10-05T15:08:03","guid":{"rendered":"https:\/\/jsoncrew.com\/?post_type=case_studies&#038;p=2454"},"modified":"2026-10-09T23:16:48","modified_gmt":"2026-10-09T21:16:48","slug":"trzy-rodziny-backdoorow-wordpress-case","status":"publish","type":"case_studies","link":"https:\/\/jsoncrew.com\/en\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/","title":{"rendered":"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress"},"content":{"rendered":"<p class=\"jc-lead\" style=\"font-size:1.3rem;line-height:1.5;font-weight:500;color:#0B1620;margin:0 0 1.8rem 0\"><strong>The client's website was unavailable for several days. Underneath: three independent backdoor families, a Chinese C&amp;C server, a Ukrainian Telegram bot and a phishing kit impersonating a Japanese store. All in one WordPress installation that looked healthy from the outside.<\/strong><\/p>\n<p>When the customer contacted us, there was not a single symptom of \u201esomething not working\u201d. There was a specific, measurable problem: the company website was unresponsive. Behind this failure there were several small signals that individually meant nothing, but together they created a picture of systematic, long-term access by third parties to the server. We finished the story in one day. We left the mechanism that made us sure that the problem had really disappeared to the client permanently. If you're looking for exactly this type of care, check out ours <a href=\"https:\/\/jsoncrew.com\/en\/oferta\/utrzymanie-i-rozwoj-stron\/\">website maintenance and development offers<\/a>.<\/p>\n<aside style=\"margin:2.2rem 0;padding:1.6rem 1.8rem;background:#FFF8E6;border-left:4px solid #E8B500;border-radius:6px\">\n<p style=\"margin:0 0 0.4rem 0;font-size:0.78rem;letter-spacing:0.14em;text-transform:uppercase;color:#8B6914;font-weight:700\">Real cost<\/p>\n<p style=\"margin:0;font-size:1.05rem;line-height:1.55\"><strong>The customer service was offline for several days<\/strong> before he came to us. Browsers showed a warning about a dangerous website, Google started removing subpages from the index, and contact forms did not accept reports.<\/p>\n<\/aside>\n<p>In the case of a company website that serves as a website and a source of leads, this is a direct path to a measurable loss:<\/p>\n<ul>\n<li>zero inquiries during the entire period of unavailability<\/li>\n<li>search engine positions to be rebuilt for weeks after returning (Google is removed from the index in a few hours, restored in a few weeks)<\/li>\n<li>loss of trust of customers who have received an error message in the meantime<\/li>\n<li>risk of permanently marking the domain as a \u201edeceptive site\u201d by Google Safe Browsing and Microsoft SmartScreen, which blocks the website in Chrome, Edge, Firefox and anti-virus warnings even after removing the code<\/li>\n<\/ul>\n<p>Our work started with <strong>recovery from failure<\/strong>: restoring the availability of the website to regular traffic was the first step, and the diagnosis and cleanup took place in parallel, only after the website was launched.<\/p>\n<h2>Industry and context<\/h2>\n<p>The client runs a company landing + offer website, based on WordPress with Elementor Pro and the Jet plug-in family. Shared hosting. A standard stack that serves hundreds of thousands of companies in Poland. That's why this case is interesting: it doesn't stand out in any way. It could have been any company's website. For comparison, <a href=\"https:\/\/jsoncrew.com\/en\/case-studies\/szkola-numerologii\/\">We made a similar WordPress case for a numerology school<\/a>: different industry, same level of complexity under the hood.<\/p>\n<h2>Starting point<\/h2>\n<p>Small, difficult to relate things started happening on the website:<\/p>\n<ul>\n<li>new files appeared periodically <code>index.php<\/code> in random plugin subfolders<\/li>\n<li>file <code>license.txt<\/code> in the main directory it had zero size and was regularly \u201emoved\u201d (changing the timestamp without changing the content) every several days<\/li>\n<li>Google Search Console showed pages indexed in Japanese that no one was publishing<\/li>\n<li>next to WordPress, under <code>\/quiz\/<\/code>, the \u201ecalculate the cost of a photovoltaic installation\u201d quiz in Polish worked, although the client does not deal with photovoltaics<\/li>\n<\/ul>\n<p>Each of these signals individually can be ignored. Together this is a textbook example of long-term disgrace.<\/p>\n<h2>Diagnosis: three backdoor families + phishing kit<\/h2>\n<p>The investigation showed that the server had been attacked several times over the years <strong>over three years<\/strong>, by different groups, with different goals. Below is a short description of each family, and under each description there is an expanded section with technical details for those interested.<\/p>\n<h3>Family 1: Japanese SEO cloak + Chinese RCE<\/h3>\n<p>Main <code>index.php<\/code> website that normally runs WordPress was modified to hold <strong>three overlapping layers of malicious code<\/strong>. An ordinary user from Poland saw a normal page. Googlebot from Japan saw a fake store. An attacker with the right parameter in the URL received remote code execution.<\/p>\n<details class=\"cs-mal-tech\" style=\"margin:1rem 0 1.6rem;padding:1.2rem 1.4rem;background:#F6F8FA;border:1px solid #E2E7EB;border-radius:6px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#0B1620\"><span style=\"color:#16C47F;margin-right:0.5rem\">\u25b8<\/span>Technical deep-dive: three layers in one file<\/summary>\n<div style=\"margin-top:1rem;line-height:1.6\">\n<ul>\n<li><strong>Cloak SEO in Japanese<\/strong>: if the request came from Google.co.jp, Yahoo.co.jp, Bing or Baidu (checked after <code>User Agent<\/code> + <code>HTTP referer<\/code>), the server responded to others <code>Location<\/code>than normal and redirected to a fake store masquerading as Askul.<\/li>\n<li><strong>\u201e2DUAN\u201d (Chinese family)<\/strong>: separate block with markers <code>2DUAN_START<\/code> i <code>2DUAN_end<\/code>, with stitched URL to C&amp;C server encoded in ROT13, symmetric key in constant <code>KK<\/code> and instance identifier in the variable <code>NN<\/code>. In addition, remote code execution by parameters <code>?pwd=X&amp;gv=Y<\/code> (password after MD5).<\/li>\n<li>At the end: a normal WordPress bootstrap so that the site does not crash for normal traffic.<\/li>\n<\/ul>\n<p>Three layers in one file strongly suggest that the server passed through successive groups of attackers, and each added its own piece.<\/p>\n<\/div>\n<\/details>\n<h3>Family 2: dropper with random hashes<\/h3>\n<p>The second family is <strong>remote loader<\/strong>, which from time to time created a new folder with a random hash and threw PHP into it, which through <code>cURL<\/code> retrieved a text response from the C&amp;C server and executed it through <code>eval<\/code>. Three generations of dropper lived in the server in parallel, at different ages. The oldest one from December 2022.<\/p>\n<details class=\"cs-mal-tech\" style=\"margin:1rem 0 1.6rem;padding:1.2rem 1.4rem;background:#F6F8FA;border:1px solid #E2E7EB;border-radius:6px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#0B1620\"><span style=\"color:#16C47F;margin-right:0.5rem\">\u25b8<\/span>Technical deep-dive: three generations, one launcher<\/summary>\n<div style=\"margin-top:1rem;line-height:1.6\">\n<ul>\n<li><code>\/f1dec\/<\/code> of December 2022 (the oldest, probably the moment of the first burglary)<\/li>\n<li><code>\/wp-content\/ad1b029e\/<\/code> of August 2026<\/li>\n<li><code>\/wp-content\/x9f8ea6\/<\/code> of September 2026 (regeneration during our diagnostic session, caught live)<\/li>\n<\/ul>\n<p>In each instance, an identical launcher with the same SHA hash. Zero <code>license.txt<\/code> in the root was their \u201ecanary\u201d: a simple marker after which the attacker knew that persistence was still alive.<\/p>\n<\/div>\n<\/details>\n<h3>Family 3: magic-URL admin creator with auto-heal<\/h3>\n<p>It was the most dangerous family because it could <strong>rebuild itself<\/strong>. One HTTP request with the appropriate parameter in the URL caused the server to create a WordPress administrator account itself and log the attacker immediately. The second file, in a hidden location, rebuilt the whole thing if someone deleted the first one.<\/p>\n<details class=\"cs-mal-tech\" style=\"margin:1rem 0 1.6rem;padding:1.2rem 1.4rem;background:#F6F8FA;border:1px solid #E2E7EB;border-radius:6px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#0B1620\"><span style=\"color:#16C47F;margin-right:0.5rem\">\u25b8<\/span>Technical deep-dive: two files, three locations, zero chance of manual cleanup<\/summary>\n<div style=\"margin-top:1rem;line-height:1.6\">\n<ul>\n<li><code>firewall.php<\/code>: responded to a specific GET parameter in the URL. One hit caused the server to create an administrator account (login and email sewn in the code) and immediately logged the attacker without the form.<\/li>\n<li><code>fixer.php<\/code>: HTTP-open regenerator. If someone removed <code>firewall.php<\/code>, one HTTP request was enough to <code>fixer.php<\/code>, so that he decodes the backup copies from base64 and puts them back on the disk, in <strong>three locations at the same time<\/strong>: in the root, in <code>mu-plugins<\/code>, in the theme folder.<\/li>\n<\/ul>\n<p>This meant that manually deleting files on the client side did nothing. As long as he lived on the server <code>fixer.php<\/code>, the other files were coming back.<\/p>\n<\/div>\n<\/details>\n<h3>Add-on: phishing kit <code>\/quiz\/<\/code><\/h3>\n<p>Regardless of the backdoors, in the subfolder <code>\/quiz\/<\/code> a quiz based on SaaS Marquiz was running. Setting up the quiz: Polish scam lead gene for photovoltaics. Leads from the form were sent in two channels: <strong>to the client's company mailbox<\/strong> (the attacker impersonated him as the sender) and <strong>on Telegram's Ukrainian bot<\/strong> (chat ID + bot token sewn in the code).<\/p>\n<aside style=\"margin:2rem 0;padding:1.4rem 1.6rem;background:#FEF1F0;border-left:4px solid #D9342B;border-radius:6px\">\n<p style=\"margin:0 0 0.4rem 0;font-size:0.78rem;letter-spacing:0.14em;text-transform:uppercase;color:#8B1F1A;font-weight:700\">Why it's dangerous<\/p>\n<p style=\"margin:0;line-height:1.55\">The external domain to which he linked the quiz had its own SMTP, which sent emails from an address on the client's domain as the sender. Technically, this meant that <strong>the client's domain was actively used as a sender of phishing emails<\/strong>. Real risk: landing the entire domain on the global SPAMhaus and Barracuda blacklists, which would mean that even legitimate company emails would stop reaching.<\/p>\n<\/aside>\n<h2>Attack timeline (reconstructed)<\/h2>\n<div style=\"margin:1.5rem 0\">\n<table style=\"width:100%;border-collapse:collapse;font-size:0.95rem\">\n<thead>\n<tr style=\"background:#0B1620;color:#fff\">\n<th style=\"padding:12px 16px;text-align:left\">Date<\/th>\n<th style=\"padding:12px 16px;text-align:left\">Event<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom:1px solid #E2E7EB\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2022-12-10<\/strong><\/td>\n<td style=\"padding:12px 16px\">First loader (<code>\/f1dec\/index.php<\/code>). Probably the moment of the original compromise by the old CVE.<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid #E2E7EB\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2025-08-12<\/strong><\/td>\n<td style=\"padding:12px 16px\">Deploy phishing kit <code>\/quiz\/<\/code> + Telegram bot.<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid #E2E7EB\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2026-08-22<\/strong><\/td>\n<td style=\"padding:12px 16px\">Second-generation dropper (<code>\/wp-content\/ad1b029e\/<\/code>).<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid #E2E7EB\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2026-08-30 14:16<\/strong><\/td>\n<td style=\"padding:12px 16px\">Batch drop: a hidden folder with a name containing quotes (anti<code>Next<\/code> trick) + <code>wp2shell-batch-guard<\/code>.<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid #E2E7EB;background:#FEF1F0\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2026-08-31 01:31<\/strong><\/td>\n<td style=\"padding:12px 16px\"><strong>Massive deploy<\/strong>: <code>firewall.php<\/code> + <code>fixer.php<\/code> + <code>wp2shell-batch-guard.php<\/code> in three locations. On the same day, the attacker <strong>replaced the WordPress core<\/strong> and overwritten <code>wp-config.php<\/code>, probably to regain control after some automatic cleanup.<\/td>\n<\/tr>\n<tr style=\"border-bottom:1px solid #E2E7EB\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2026-09-03 11:33<\/strong><\/td>\n<td style=\"padding:12px 16px\">During our session: third generation dropper (<code>\/wp-content\/x9f8ea6\/<\/code>) appears live. We catch her on the fly.<\/td>\n<\/tr>\n<tr style=\"background:#E8F8EF\">\n<td style=\"padding:12px 16px;white-space:nowrap\"><strong>2026-09-03 11:52<\/strong><\/td>\n<td style=\"padding:12px 16px\"><strong>Full cleanup of all three families + phishing putty.<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Three years of persistence, including a whole series of active surgeries in the last month. The customer didn't know anything.<\/p>\n<h2>What we have done<\/h2>\n<h3>Step 1: Restore availability<\/h3>\n<p>The first hours went to make the site work at all, no matter what we find underneath. Shutting down traffic from the outside, restoring a clean entry point (<code>index.php<\/code>), removing the obvious 500s. Only then did the correct diagnosis begin.<\/p>\n<h3>Step 2: Enumerate all droppers<\/h3>\n<p>Full webroot scanning after characteristic markers (<code>goto<\/code> Base64, <code>2DUAN<\/code>, <code>eval(curl(...))<\/code>, unusual quotation marks in folder names as an anti-lstat trick). Each file found: backup off-site + deletion.<\/p>\n<h3>Step 3: Cutting the regeneration chain<\/h3>\n<p>Family 3 regenerated for <code>fixer.php<\/code>. While <code>fixer.php<\/code> he was alive, the other files were coming back. We had to establish that <code>fixer.php<\/code> exists in <strong>three locations at the same time<\/strong> and remove all three in one pass. After the first attempt, in which we deleted only a copy in the theme, the files returned within a few minutes.<\/p>\n<h3>Step 4: Phishing kit + Telegram<\/h3>\n<p>Deleting an entire directory <code>\/quiz\/<\/code> and the related Marquiz account (we gave the client a list of steps to carry out at their home). Blocking shipments from own domain as a sender (SPF + DMARC <code>===reject<\/code>).<\/p>\n<h3>Step 5: Watcher mu-plugin (stays permanently)<\/h3>\n<p>We have built a dedicated mu-plugin, let's call it a \u201eforensic watcher\u201d that lives in <code>wp-content\/mu-plugins\/<\/code> and boots up with every PHP request. It is part of the package that we attach to each contract as part of <a href=\"https:\/\/jsoncrew.com\/en\/oferta\/utrzymanie-i-rozwoj-stron\/\">website maintenance and development<\/a>.<\/p>\n<details class=\"cs-mal-tech\" style=\"margin:1rem 0 1.6rem;padding:1.2rem 1.4rem;background:#F6F8FA;border:1px solid #E2E7EB;border-radius:6px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#0B1620\"><span style=\"color:#16C47F;margin-right:0.5rem\">\u25b8<\/span>What exactly does the watcher do (list of functions)<\/summary>\n<div style=\"margin-top:1rem;line-height:1.6\">\n<ul>\n<li><strong>Logs all<\/strong>, What is changing <code>.PHP<\/code> on the server: new file, modification, deletion. Separate log with full path + timestamp.<\/li>\n<li><strong>Logs each attack attempt<\/strong>: request with known signatures of the three backdoor families. Separate log, separate file.<\/li>\n<li><strong>Blocks 403<\/strong>: before the attacker gets a response, the server returns 403 Forbidden to known signatures. So even if in the future some miracle appears on the server <code>firewall.php<\/code>, the magic URL won't work anyway.<\/li>\n<li><strong>Diagnostic endpoints<\/strong> token-protected: status, baseline, change list, user list, cron list, grep by file content, autoremediation. One HTTP request and we know if anything on the server has changed in the last 24 hours.<\/li>\n<li><strong>Logs outside webroot<\/strong>: log files go to the directory higher than the publicly available webroot, additionally from <code>.htaccess deny<\/code>. Even if the attacker gets FTP access again, he will not see what exactly we know.<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h3>Step 6: Database Audit<\/h3>\n<p>In addition, we checked through the watcher that <strong>there is no trash from attackers in the base<\/strong>: <code>wp_users<\/code> (the only admin is a customer account, no accounts created by attackers), <code>wp_options.autoload<\/code> (clean), WP-Cron (clean, no registered hooks that cannot be assigned to standard plugins).<\/p>\n<h2>Why it happened in the first place<\/h2>\n<p>Three independent vectors are rare, but the specific reasons attackers enter are one of three things in 95% cases:<\/p>\n<ol>\n<li><strong>Outdated plugins with public CVE<\/strong>. The server had several plugins from the Jet family version from a dozen or so months ago. One of them in the period 2022-2023 had a publicly described gap allowing for authenticated file upload.<\/li>\n<li><strong>Weak admin password or leak from external service<\/strong> (data breach). The original compromise may not have been \u201etechnical\u201d: it is enough that someone used the same password in several places, and one of them leaked.<\/li>\n<li><strong>Shared Hosting<\/strong>. Some documented attacks on shared hosting involved passing from one compromised side of a neighbor to the other through a shared <code>TMP<\/code> or the default directory rights.<\/li>\n<\/ol>\n<aside style=\"margin:2rem 0;padding:1.4rem 1.6rem;background:#EAF4FF;border-left:4px solid #0066CC;border-radius:6px\">\n<p style=\"margin:0 0 0.4rem 0;font-size:0.78rem;letter-spacing:0.14em;text-transform:uppercase;color:#004480;font-weight:700\">Insight<\/p>\n<p style=\"margin:0;line-height:1.55\">In this case, <strong>najbardziej prawdopodobny jest wektor nr 1<\/strong>, bo pierwsza data w\u0142amania (2022-12-10) pokrywa si\u0119 z masowym fuzzingiem jednej konkretnej luki w Jet-wtyczkach po jej opublikowaniu. Kr\u00f3tko: kto\u015b pu\u015bci\u0142 scanner po ca\u0142ym internecie i strona klienta akurat na niego wpad\u0142a. Nic osobistego.<\/p>\n<\/aside>\n<h2>Rezultaty w liczbach<\/h2>\n<figure style=\"margin:1.8rem 0 2.4rem;padding:1.8rem;background:#F6F8FA;border-radius:12px;border-top:4px solid #16C47F\"><figcaption style=\"font-size:0.72rem;letter-spacing:0.16em;text-transform:uppercase;color:#5B6B78;font-weight:700;margin-bottom:0.6rem\">Interaktywny wykres \u00b7 najed\u017a na punkt<\/figcaption><h3 style=\"margin:0 0 0.4rem 0;font-size:1.3rem;line-height:1.3\">Trzy lata ciszy, dziesi\u0119\u0107 dni erupcji, jedna minuta cleanupu<\/h3>\n<p style=\"margin:0 0 1.4rem 0;color:#5B6B78;font-size:0.95rem;line-height:1.5\">Skumulowana liczba z\u0142o\u015bliwych artefakt\u00f3w na serwerze w czasie. Ka\u017cdy punkt to osobny deploy atakuj\u0105cego. Zielony punkt na ko\u0144cu to nasza interwencja.<\/p>\n<div style=\"position:relative;width:100%;overflow-x:auto\">\n<svg viewbox=\"0 0 1000 420\" style=\"width:100%;height:auto;min-width:600px;display:block\" role=\"img\" aria-label=\"Attack escalation chart: cumulative number of malicious artifacts between December 2022 and September 2026\"><rect x=\"60\" y=\"40\" width=\"880\" height=\"320\" fill=\"#fff\" stroke=\"none\"\/><line x1=\"60\" y1=\"360\" x2=\"940\" y2=\"360\" stroke=\"#CBD5E0\" stroke-width=\"1.5\"\/><line x1=\"60\" y1=\"40\" x2=\"60\" y2=\"360\" stroke=\"#CBD5E0\" stroke-width=\"1.5\"\/><line x1=\"60\" y1=\"307\" x2=\"940\" y2=\"307\" stroke=\"#E2E7EB\" stroke-width=\"1\" stroke-dasharray=\"4,4\"\/><line x1=\"60\" y1=\"227\" x2=\"940\" y2=\"227\" stroke=\"#E2E7EB\" stroke-width=\"1\" stroke-dasharray=\"4,4\"\/><line x1=\"60\" y1=\"94\" x2=\"940\" y2=\"94\" stroke=\"#E2E7EB\" stroke-width=\"1\" stroke-dasharray=\"4,4\"\/><text x=\"52\" y=\"365\" text-anchor=\"end\" font-size=\"12\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">0<\/text><text x=\"52\" y=\"312\" text-anchor=\"end\" font-size=\"12\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">2<\/text><text x=\"52\" y=\"232\" text-anchor=\"end\" font-size=\"12\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">5<\/text><text x=\"52\" y=\"99\" text-anchor=\"end\" font-size=\"12\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">10<\/text><text x=\"52\" y=\"45\" text-anchor=\"end\" font-size=\"12\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">12<\/text><text x=\"20\" y=\"200\" text-anchor=\"middle\" font-size=\"11\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\" transform=\"rotate(-90 20 200)\">Skumulowane artefakty<\/text><path d=\"M60,333 L207,307 L353,280 L500,227 L647,94 L793,67 L940,360 L940,360 L60,360 Z\" fill=\"#D9342B\" fill-opacity=\"0.08\"\/><polyline points=\"60,333 207,307 353,280 500,227 647,94 793,67\" fill=\"none\" stroke=\"#D9342B\" stroke-width=\"3\" stroke-linejoin=\"round\" stroke-linecap=\"round\"\/><line x1=\"793\" y1=\"67\" x2=\"940\" y2=\"360\" stroke=\"#16C47F\" stroke-width=\"3\" stroke-linejoin=\"round\" stroke-linecap=\"round\" stroke-dasharray=\"8,4\"\/><line x1=\"940\" y1=\"40\" x2=\"940\" y2=\"360\" stroke=\"#16C47F\" stroke-width=\"1.5\" stroke-dasharray=\"4,4\" opacity=\"0.5\"\/><line x1=\"500\" y1=\"40\" x2=\"940\" y2=\"40\" stroke=\"#D9342B\" stroke-width=\"1\" stroke-dasharray=\"4,4\" opacity=\"0.5\"\/><text x=\"720\" y=\"30\" text-anchor=\"middle\" font-size=\"12\" fill=\"#D9342B\" font-weight=\"700\" font-family=\"system-ui,sans-serif\">10 dni intensywnej eskalacji<\/text><g style=\"cursor:help\"><circle cx=\"60\" cy=\"333\" r=\"7\" fill=\"#D9342B\" stroke=\"#fff\" stroke-width=\"2\"><title>2022-12-10 \u00b7 Pierwszy loader \/f1dec\/index.php \u2014 moment pierwotnej kompromitacji | Skumulowane artefakty: 1<\/title><\/circle><circle cx=\"207\" cy=\"307\" r=\"7\" fill=\"#D9342B\" stroke=\"#fff\" stroke-width=\"2\"><title>2025-08-12 \u00b7 Deploy phishing kit \/quiz\/ + ukrai\u0144ski Telegram bot | Skumulowane artefakty: 2<\/title><\/circle><circle cx=\"353\" cy=\"280\" r=\"7\" fill=\"#D9342B\" stroke=\"#fff\" stroke-width=\"2\"><title>2026-08-22 \u00b7 Second-generation dropper (\/wp-content\/ad1b029e\/) | Skumulowane artefakty: 3<\/title><\/circle><circle cx=\"500\" cy=\"227\" r=\"7\" fill=\"#D9342B\" stroke=\"#fff\" stroke-width=\"2\"><title>2026-08-30 14:16 \u00b7 Batch drop: ukryty folder z anti-lstat trick + wp2shell-batch-guard | Skumulowane artefakty: 5<\/title><\/circle><circle cx=\"647\" cy=\"94\" r=\"10\" fill=\"#D9342B\" stroke=\"#fff\" stroke-width=\"2.5\"><title>2026-08-31 01:31 \u00b7 MASYWNY DEPLOY: firewall + fixer + wp2shell w trzech lokalizacjach jednocze\u015bnie, plus podmiana rdzenia WordPressa | Skumulowane artefakty: 10<\/title><\/circle><circle cx=\"793\" cy=\"67\" r=\"8\" fill=\"#D9342B\" stroke=\"#fff\" stroke-width=\"2\"><title>2026-09-03 11:33 \u00b7 Trzecia generacja droppera (\/wp-content\/x9f8ea6\/) \u2014 pojawia si\u0119 w trakcie naszej sesji, z\u0142apana na \u017cywo | Skumulowane artefakty: 11<\/title><\/circle><circle cx=\"940\" cy=\"360\" r=\"11\" fill=\"#16C47F\" stroke=\"#fff\" stroke-width=\"3\"><title>2026-09-03 11:52 \u00b7 NASZA INTERWENCJA \u2014 pe\u0142ny cleanup wszystkich trzech rodzin backdoor\u00f3w + phishing kitu. Czas od pierwszej generacji droppera: 3 lata, 2 miesi\u0105ce, 24 dni | Pozosta\u0142o: 0<\/title><\/circle><\/g><text x=\"60\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">12.2022<\/text><text x=\"207\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">08.2025<\/text><text x=\"353\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">22.08.26<\/text><text x=\"500\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">30.08<\/text><text x=\"647\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">31.08<\/text><text x=\"793\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">03.09 11:33<\/text><text x=\"940\" y=\"385\" text-anchor=\"middle\" font-size=\"10\" fill=\"#16C47F\" font-weight=\"700\" font-family=\"system-ui,sans-serif\">cleanup<\/text><g font-family=\"system-ui,sans-serif\" font-size=\"11\"><rect x=\"60\" y=\"402\" width=\"12\" height=\"12\" fill=\"#D9342B\"\/><text x=\"78\" y=\"412\" fill=\"#5B6B78\">deploy atakuj\u0105cego<\/text><rect x=\"220\" y=\"402\" width=\"12\" height=\"12\" fill=\"#16C47F\"\/><text x=\"238\" y=\"412\" fill=\"#5B6B78\">nasza interwencja (cleanup)<\/text><\/g><\/svg>\n<\/div>\n<\/figure>\n<div style=\"display:grid;grid-template-columns:1fr 1fr;gap:1.5rem;margin:2rem 0;align-items:stretch\">\n<div style=\"padding:1.6rem;background:#F6F8FA;border-radius:10px;border-top:3px solid #D9342B\">\n<p style=\"margin:0 0 0.4rem 0;font-size:0.72rem;letter-spacing:0.16em;text-transform:uppercase;color:#8B1F1A;font-weight:700\">Co znale\u017ali\u015bmy<\/p>\n<h3 style=\"margin:0 0 1rem 0;font-size:1.15rem;line-height:1.3\">Podzia\u0142 szkodliwych artefakt\u00f3w<\/h3>\n<div style=\"display:flex;align-items:center;gap:1.4rem;flex-wrap:wrap\">\n<svg viewbox=\"0 0 100 100\" style=\"width:120px;height:120px;flex-shrink:0\" role=\"img\" aria-label=\"Pie chart: 3 backdoor families + phishing kit\"><circle cx=\"50\" cy=\"50\" r=\"38\" fill=\"none\" stroke=\"#E2E7EB\" stroke-width=\"14\"\/><circle cx=\"50\" cy=\"50\" r=\"38\" fill=\"none\" stroke=\"#D9342B\" stroke-width=\"14\" stroke-dasharray=\"83.78 238.76\" stroke-dashoffset=\"0\" transform=\"rotate(-90 50 50)\"><title>Rodzina 1: Japanese SEO cloak + chi\u0144ski 2DUAN RCE<\/title><\/circle><circle cx=\"50\" cy=\"50\" r=\"38\" fill=\"none\" stroke=\"#E8B500\" stroke-width=\"14\" stroke-dasharray=\"83.78 238.76\" stroke-dashoffset=\"-83.78\" transform=\"rotate(-90 50 50)\"><title>Rodzina 2: Dropper z losowymi hashami (3 generacje)<\/title><\/circle><circle cx=\"50\" cy=\"50\" r=\"38\" fill=\"none\" stroke=\"#0066CC\" stroke-width=\"14\" stroke-dasharray=\"83.78 238.76\" stroke-dashoffset=\"-167.55\" transform=\"rotate(-90 50 50)\"><title>Family 3: magic-URL admin creator with auto-heal<\/title><\/circle><circle cx=\"50\" cy=\"50\" r=\"38\" fill=\"none\" stroke=\"#6B46C1\" stroke-width=\"14\" stroke-dasharray=\"83.78 238.76\" stroke-dashoffset=\"-251.33\" transform=\"rotate(-90 50 50)\"><title>Add-on: phishing kit \/quiz\/ z Telegram botem<\/title><\/circle><text x=\"50\" y=\"47\" text-anchor=\"middle\" font-size=\"22\" font-weight=\"800\" fill=\"#0B1620\" font-family=\"Georgia,serif\">4<\/text><text x=\"50\" y=\"62\" text-anchor=\"middle\" font-size=\"8\" fill=\"#5B6B78\" font-family=\"system-ui,sans-serif\">wektory<\/text><\/svg><\/p>\n<ul style=\"margin:0;padding:0;list-style:none;flex:1;min-width:180px;font-size:0.9rem;line-height:1.6\">\n<li style=\"padding:0.3rem 0;border-bottom:1px solid #E2E7EB\"><span style=\"display:inline-block;width:10px;height:10px;background:#D9342B;border-radius:2px;margin-right:0.6rem;vertical-align:middle\"><\/span>Japanese cloak + 2DUAN<\/li>\n<li style=\"padding:0.3rem 0;border-bottom:1px solid #E2E7EB\"><span style=\"display:inline-block;width:10px;height:10px;background:#E8B500;border-radius:2px;margin-right:0.6rem;vertical-align:middle\"><\/span>Dropper (3 generacje)<\/li>\n<li style=\"padding:0.3rem 0;border-bottom:1px solid #E2E7EB\"><span style=\"display:inline-block;width:10px;height:10px;background:#0066CC;border-radius:2px;margin-right:0.6rem;vertical-align:middle\"><\/span>magic-URL admin<\/li>\n<li style=\"padding:0.3rem 0\"><span style=\"display:inline-block;width:10px;height:10px;background:#6B46C1;border-radius:2px;margin-right:0.6rem;vertical-align:middle\"><\/span>Phishing kit \/quiz\/<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div style=\"padding:1.6rem;background:#F6F8FA;border-radius:10px;border-top:3px solid #16C47F\">\n<p style=\"margin:0 0 0.4rem 0;font-size:0.72rem;letter-spacing:0.16em;text-transform:uppercase;color:#0A6E42;font-weight:700\">Czas: atak vs reakcja<\/p>\n<h3 style=\"margin:0 0 1rem 0;font-size:1.15rem;line-height:1.3\">Por\u00f3wnanie skal<\/h3>\n<div style=\"display:flex;flex-direction:column;gap:1rem\">\n<div>\n<div style=\"display:flex;justify-content:space-between;margin-bottom:0.4rem;font-size:0.85rem\"><span style=\"color:#5B6B78\">Czas, przez kt\u00f3ry atak trwa\u0142 niezauwa\u017cony<\/span><span style=\"font-weight:700;color:#D9342B\">3 years<\/span><\/div>\n<div style=\"height:12px;background:#E2E7EB;border-radius:6px;overflow:hidden\">\n<div style=\"width:100%;height:100%;background:linear-gradient(90deg,#D9342B,#F4C430);border-radius:6px\"><\/div>\n<\/div>\n<\/div>\n<div>\n<div style=\"display:flex;justify-content:space-between;margin-bottom:0.4rem;font-size:0.85rem\"><span style=\"color:#5B6B78\">Downtime zanim klient dotar\u0142 do nas<\/span><span style=\"font-weight:700;color:#E8B500\">a few days<\/span><\/div>\n<div style=\"height:12px;background:#E2E7EB;border-radius:6px;overflow:hidden\">\n<div style=\"width:12%;height:100%;background:#E8B500;border-radius:6px\"><\/div>\n<\/div>\n<\/div>\n<div>\n<div style=\"display:flex;justify-content:space-between;margin-bottom:0.4rem;font-size:0.85rem\"><span style=\"color:#5B6B78\">Pe\u0142ny cleanup po przywr\u00f3ceniu<\/span><span style=\"font-weight:700;color:#16C47F\">1 day<\/span><\/div>\n<div style=\"height:12px;background:#E2E7EB;border-radius:6px;overflow:hidden\">\n<div style=\"width:3%;height:100%;background:#16C47F;border-radius:6px\"><\/div>\n<\/div>\n<\/div>\n<div>\n<div style=\"display:flex;justify-content:space-between;margin-bottom:0.4rem;font-size:0.85rem\"><span style=\"color:#5B6B78\">Wykrycie wracaj\u0105cego droppera (watcher)<\/span><span style=\"font-weight:700;color:#16C47F\">minuty<\/span><\/div>\n<div style=\"height:12px;background:#E2E7EB;border-radius:6px;overflow:hidden\">\n<div style=\"width:1%;height:100%;background:#16C47F;border-radius:6px\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p style=\"margin:1rem 0 0 0;font-size:0.78rem;color:#9BA3AD;line-height:1.5\">Paski proporcjonalne. Watcher kompresuje czas detekcji o ok. tysi\u0105c razy wzgl\u0119dem stanu pierwotnego.<\/p>\n<\/div>\n<\/div>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(180px,1fr));gap:1rem;margin:1.5rem 0\">\n<div style=\"padding:1.4rem;background:#0B1620;color:#fff;border-radius:10px;position:relative;overflow:hidden\">\n<div style=\"font-size:0.7rem;letter-spacing:0.16em;text-transform:uppercase;color:#16C47F;font-weight:700;margin-bottom:0.6rem\">Status monitoringu<\/div>\n<div style=\"font-size:2.2rem;font-weight:800;line-height:1;font-family:Georgia,serif;color:#fff\">0<\/div>\n<div style=\"margin-top:0.6rem;font-size:0.9rem;color:#8B96A3\">nawrot\u00f3w od wdro\u017cenia watchera<\/div>\n<p><svg viewbox=\"0 0 24 24\" style=\"position:absolute;right:1rem;top:1rem;width:28px;height:28px;opacity:0.3\" fill=\"none\" stroke=\"#16C47F\" stroke-width=\"2\"><path d=\"M12 2 L2 7 L2 17 L12 22 L22 17 L22 7 Z\"\/><path d=\"M9 12 L11 14 L15 10\"\/><\/svg>\n<\/div>\n<div style=\"padding:1.4rem;background:#F6F8FA;border-radius:10px;border-top:3px solid #0B1620\">\n<div style=\"font-size:0.7rem;letter-spacing:0.16em;text-transform:uppercase;color:#5B6B78;font-weight:700;margin-bottom:0.6rem\">Zebrane artefakty<\/div>\n<div style=\"font-size:2.2rem;font-weight:800;line-height:1;font-family:Georgia,serif;color:#0B1620\">&gt;12<\/div>\n<div style=\"margin-top:0.6rem;font-size:0.9rem;color:#5B6B78\">szkodliwych plik\u00f3w w r\u00f3\u017cnych lokalizacjach<\/div>\n<\/div>\n<div style=\"padding:1.4rem;background:#F6F8FA;border-radius:10px;border-top:3px solid #0B1620\">\n<div style=\"font-size:0.7rem;letter-spacing:0.16em;text-transform:uppercase;color:#5B6B78;font-weight:700;margin-bottom:0.6rem\">Dowody w DB<\/div>\n<div style=\"font-size:2.2rem;font-weight:800;line-height:1;font-family:Georgia,serif;color:#0B1620\">0 \/ 0 \/ 0<\/div>\n<div style=\"margin-top:0.6rem;font-size:0.9rem;color:#5B6B78\">obcych kont \u00b7 opcji \u00b7 hook\u00f3w crona<\/div>\n<\/div>\n<\/div>\n<h2>Czego nauczy\u0142 nas ten case<\/h2>\n<h3>1. Backdoory potrafi\u0105 wsp\u00f3\u0142istnie\u0107<\/h3>\n<p>Przyzwyczajenie \u201ejeden atak = jeden rodzaj szkodnika\u201d jest myl\u0105ce. Je\u015bli strona by\u0142a wystawiona i podatna przez lata, mog\u0142a by\u0107 skompromitowana kilka razy, przez r\u00f3\u017cne grupy, z r\u00f3\u017cnymi celami. Ka\u017cda z nich zostawia w\u0142asny mechanizm persistencji i ka\u017cdy z nich trzeba znale\u017a\u0107 osobno. Zatrzymanie si\u0119 po usuni\u0119ciu pierwszego pliku to typowy b\u0142\u0105d.<\/p>\n<h3>2. Auto-heal to g\u0142\u00f3wny mechanizm prze\u017cycia nowoczesnego malware<\/h3>\n<p>Pliki w widocznych miejscach to przyn\u0119ta. Prawdziwym mechanizmem prze\u017cycia jest <strong>regenerator<\/strong> w nieoczywistej lokalizacji, kt\u00f3ry odbudowuje widoczne pliki za ka\u017cdym razem, gdy kto\u015b je usunie. Je\u015bli po \u201ewyczyszczeniu\u201d strony pliki wracaj\u0105 w ci\u0105gu kilku godzin, znaczy to, \u017ce czyszczono tylko objawy.<\/p>\n<h3>3. Twoja domena mo\u017ce by\u0107 narz\u0119dziem, nawet je\u015bli Twoja strona wygl\u0105da OK<\/h3>\n<p>Phishing kit z Telegram botem nie zrobi\u0142 nic widocznego z perspektywy odwiedzaj\u0105cego stron\u0119. Nie pokazywa\u0142 reklam, nie przekierowywa\u0142, nie zmienia\u0142 SEO. Po prostu <em>wykorzystywa\u0142<\/em> domen\u0119 jako nadawc\u0119. Dla Google, Microsoftu, Barracudy i reszty operator\u00f3w antyspamowych wygl\u0105da to tak, jakby to Ty wysy\u0142a\u0142e\u015b phishing. Konsekwencje (SPAMhaus blacklist, utrata deliverability) s\u0105 powa\u017cniejsze ni\u017c defacement.<\/p>\n<h3>4. Monitoring plik\u00f3w to nie luksus<\/h3>\n<p>Wi\u0119kszo\u015b\u0107 klient\u00f3w rozpoznaje atak, dopiero gdy co\u015b wizualnie si\u0119 zepsuje: strona nie \u0142aduje si\u0119, pojawia si\u0119 ostrze\u017cenie Chrome \u201edeceptive site\u201d, Google wywala z indeksu. W tym momencie szkodliwa aktywno\u015b\u0107 na serwerze trwa cz\u0119sto miesi\u0105cami. <strong>Prosty watcher, kt\u00f3ry loguje zmiany <code>.PHP<\/code>, daje czas reakcji liczony w godzinach, nie w miesi\u0105cach.<\/strong> To standardowy element ka\u017cdej naszej umowy <a href=\"https:\/\/jsoncrew.com\/en\/oferta\/utrzymanie-i-rozwoj-stron\/\">utrzymaniowej<\/a>.<\/p>\n<h3>5. Backups before the X date contain backdoors<\/h3>\n<p>The standard reflex after detecting a compromise (\u201eI will restore the backup from a week ago\u201d) would not work in this case. The backup from a week ago contained a complete set of backdoors. Backup from a year ago, too. <strong>The only way is a full forensic cleanup + fresh backups from scratch.<\/strong><\/p>\n<section class=\"cs-seo-article\" id=\"poradnik\">\n<h2>WordPress backdoor: how to detect it and remove it so it doesn't come back<\/h2>\n<p class=\"cs-seo-lead\">This guide is for owners of business websites on WordPress who suspect a hack or have already \u201ccleaned\u201d the site once, only for the strange files to come back. We answer the question of how to remove a WordPress backdoor in a way that closes the case, not just treats the symptoms.<\/p>\n<h3>What a WordPress backdoor is and why it stays invisible for so long<\/h3>\n<p>A WordPress backdoor is a piece of PHP code that gives an attacker persistent access to the server regardless of the passwords in the admin panel. It can create administrator accounts, download and execute code from an external server, or swap content for selected visitors.<\/p>\n<p>The key trait: a well-written backdoor doesn't break the site. Ordinary users see a normal website, because the malicious code launches WordPress at the end anyway. In the case described above, the main index.php file contained three layers of foreign code, and for more than three years the site looked healthy from the outside.<\/p>\n<p>Owners usually find out about the problem only when the browser shows a dangerous site warning, Google starts dropping pages from its index, or the site stops responding.<\/p>\n<h3>Hacked WordPress site: warning signs you shouldn't ignore<\/h3>\n<p>A single symptom is easy to dismiss. Together, they form a pattern of long-term compromise. It\u2019s worth acting if you see even a few of the following:<\/p>\n<ul>\n<li>new index.php files in random plugin subfolders or directories with hash-like names (e.g., a string of letters and digits in wp-content),<\/li>\n<li>zero-byte files whose modification date changes regularly without any change in content,<\/li>\n<li>pages in a foreign language in Google Search Console that nobody published,<\/li>\n<li>subdirectories with content unrelated to the company, e.g. forms, quizzes, landing pages,<\/li>\n<li>administrator accounts nobody created, or unknown WP-Cron jobs,<\/li>\n<li>reports from customers about emails sent \u201cfrom your domain\u201d that you didn't send.<\/li>\n<\/ul>\n<p>In the case described, all these signs were visible long before the outage. An empty license.txt file in the root directory served attackers as a marker that their access was still working.<\/p>\n<h3>How to remove a backdoor from WordPress: the order of steps<\/h3>\n<p>The most common mistake is deleting suspicious files one by one as you find them. An effective process looks different:<\/p>\n<ul>\n<li><strong>Restoring availability.<\/strong> A clean entry point (index.php), traffic limiting, and eliminating 500 errors. Diagnosis runs in parallel, but the site has to work first.<\/li>\n<li><strong>Preserving a copy of the evidence.<\/strong> Every file found is copied off the server before it's deleted. Without that, you won't be able to reconstruct what happened and since when.<\/li>\n<li><strong>Full enumeration.<\/strong> Scanning the entire webroot for characteristic patterns, rather than browsing folders \u201cby eye.\u201d<\/li>\n<li><strong>Breaking the regeneration chain.<\/strong> First, you find every copy of the mechanism that restores the other files and remove them all in a single pass.<\/li>\n<li><strong>Cleanup beyond the files.<\/strong> Database, email, DNS, and third-party service accounts.<\/li>\n<li><strong>Continuous monitoring.<\/strong> A mechanism that will alert you if anything comes back.<\/li>\n<\/ul>\n<h3>Scanning PHP files: what to look for in the webroot<\/h3>\n<p>Security plugins catch known signatures, but backdoors are often obfuscated. It's worth searching .php files for a few patterns: eval constructs with content fetched via curl, long base64 strings combined with goto, ROT13-encoded text, and unusual characters (e.g. quotation marks) in directory names that make them harder to list.<\/p>\n<p>The second avenue is comparing the WordPress core with the official version. In the implementation described, the attacker replaced core files and overwrote wp-config.php. Such changes are visible only when compared against a clean copy, not by browsing the admin panel.<\/p>\n<p>The third area is the mu-plugins directory and the theme folder. Files in mu-plugins always load and don't appear in the regular plugin list, which makes them a convenient hiding place for an attacker.<\/p>\n<h3>Malware with auto-heal: why files come back after deletion<\/h3>\n<p>If files come back a few hours after the site was \u201ccleaned,\u201d the symptoms were removed, not the cause. Modern backdoors have a regenerator: a separate file in a non-obvious location that, with a single HTTP request, restores everything that was deleted from a backup copy (e.g. base64-encoded).<\/p>\n<p>In the case described, the regenerator sat in three locations at once: in the root directory, in mu-plugins, and in the theme folder. After the first attempt, in which only the copy in the theme was removed, the files came back within minutes. Only removing all three at once closed the loop.<\/p>\n<p>The second trap is several malware families coexisting. A site that's been vulnerable for years often gets taken over several times, by different groups. Here there were three independent backdoor families and a separate phishing kit. Stopping after finding the first family would have meant the others kept running.<\/p>\n<h3>Database, email, and backups after a hack<\/h3>\n<p>Files aren't everything. After the cleanup, you need to check the wp_users table (for unknown administrators), autoloaded options in wp_options, and registered WP-Cron jobs. In the case described, the database turned out to be clean, but without this verification there would have been no way to confirm it.<\/p>\n<p>Email is a separate issue. A phishing kit hidden in a subdirectory was sending emails with the client\u2019s domain address as the sender. To anti-spam operators, this looks as if the company itself were sending phishing, and the result can be the domain getting blacklisted. The protection is a correct SPF record and a DMARC policy set to reject.<\/p>\n<p>The last thing is backups. The reflex \u201cI'll restore last week's backup\u201d doesn't work if the breach is several years old. Here, both the backup from a week ago and the one from a year ago contained the full set of backdoors. After a complete cleanup, you need to start a fresh series of backups from scratch.<\/p>\n<h3>WordPress file change monitoring instead of yet another cleanup<\/h3>\n<p>The most common causes of a breach are outdated plugins with a published vulnerability, weak or reused administrator passwords, or shared hosting neighbors. Updates and passwords are the foundation, but they don't tell you that something has already happened.<\/p>\n<p>That\u2019s why, after the cleanup, the client received an mu-plugin that logs every change to .php files, blocks requests with known signatures of these backdoor families with a 403 code, and keeps the logs outside the public directory. Detecting a returning dropper takes minutes, not years. Since this mechanism was deployed, there has been no recurrence.<\/p>\n<p>If you have a company website on WordPress and nobody is monitoring the server from the inside, a good first step is a review of all .php files in the webroot and the list of administrator accounts. Such a review shows whether any WordPress backdoor is running on the server before the site stops responding.<\/p>\n<p class=\"cs-seo-links\">We provide ongoing monitoring, updates, and incident response as part of <a href=\"https:\/\/jsoncrew.com\/en\/oferta\/utrzymanie-i-rozwoj-stron\/\">website maintenance and development<\/a>; you can check the state of your website by ordering <a href=\"https:\/\/jsoncrew.com\/en\/pobierz-audyt\/\">website audit<\/a>, and if you suspect an active breach, the fastest route is through <a href=\"https:\/\/jsoncrew.com\/en\/kontakt\/\">direct contact<\/a>.<\/p>\n<\/section>\n<h2>Who this case is important for<\/h2>\n<ul>\n<li>Owners of company websites on WordPress who \u201ehave hosting from an agency\u201d and do not know who is responsible for its security<\/li>\n<li>Companies that have stopped updating plugins because \u201eit works, do not move\u201d<\/li>\n<li>Anyone who has seen strange files on their site <code>index.php<\/code> in unexpected locations and removed them manually, assuming it was the end of the matter<\/li>\n<\/ul>\n<p>If this sounds familiar, a good first step is <strong>audit of all files <code>.PHP<\/code> in server webroot + list of administrative accounts in WordPress<\/strong>. Such an audit usually takes us a few hours, and it shows whether the problem exists at all. Even more cases <a href=\"https:\/\/jsoncrew.com\/en\/zasoby\/\">you will find in the resources<\/a>, the full offer is in <a href=\"https:\/\/jsoncrew.com\/en\/oferta\/\">covered by the offer<\/a>.<\/p>\n<section style=\"margin:3rem 0 1rem;padding:2.5rem 2rem;background:linear-gradient(135deg,#0B1620 0%,#1A2A38 100%);color:#fff;border-radius:12px;text-align:center\">\n<p style=\"margin:0 0 0.6rem 0;font-size:0.78rem;letter-spacing:0.18em;text-transform:uppercase;color:#16C47F;font-weight:700\">You don't want to know you have a backdoor<\/p>\n<h2 style=\"margin:0 0 1rem 0;color:#fff;font-size:clamp(1.6rem,3.5vw,2.4rem);line-height:1.2;letter-spacing:-0.02em\">...when the page is already lying<\/h2>\n<p style=\"margin:0 0 1.8rem 0;max-width:620px;margin-left:auto;margin-right:auto;color:#CBD5E0;font-size:1.05rem;line-height:1.6\">This case describes the page we got in the crash. Almost everything could be avoided if someone guarded the server from the inside: monitored file changes, updated plugins, kept backups, watched attempts of attacks. This is our service.<\/p>\n<p style=\"margin:0 0 1rem 0\">\n<a href=\"https:\/\/jsoncrew.com\/en\/oferta\/utrzymanie-i-rozwoj-stron\/\" style=\"display:inline-block;padding:1rem 2rem;background:#16C47F;color:#0B1620;font-weight:700;text-decoration:none;border-radius:8px;font-size:1.05rem\">See the offer: maintenance and development of the parties \u2192<\/a>\n<\/p>\n<p style=\"margin:0;font-size:0.9rem;color:#8B96A3\">or <a href=\"https:\/\/jsoncrew.com\/en\/kontakt\/\" style=\"color:#16C47F;text-decoration:underline\">write to us directly<\/a>, we'll do the audit without obligation.<\/p>\n<\/section>","protected":false},"excerpt":{"rendered":"<p>Strona klienta by\u0142a offline przez kilka dni. Pod spodem trzy rodziny backdoor\u00f3w, chi\u0144ski C&amp;C i phishing kit. Trzy lata niewykrytej obecno\u015bci z\u0142apane w jeden dzie\u0144.<\/p>","protected":false},"featured_media":2459,"template":"","meta":{"_acf_changed":false,"footnotes":""},"brevo_track":[],"class_list":["post-2454","case_studies","type-case_studies","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.8 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Backdoor WordPress: 3 rodziny, cleanup w 1 dzie\u0144 | JSON Crew<\/title>\n<meta name=\"description\" content=\"Backdoor WordPress przez 3 lata: trzy rodziny malware, regenerator w 3 miejscach i phishing z domeny klienta. Jak usun\u0119li\u015bmy wszystko w jeden dzie\u0144.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jsoncrew.com\/en\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress (case study)\" \/>\n<meta property=\"og:description\" content=\"Strona by\u0142a offline kilka dni. Pod spodem trzy niezale\u017cne rodziny z\u0142o\u015bliwego kodu + phishing kit. Jak diagnozujemy i czy\u015bcimy kompromitacj\u0119 WordPress.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jsoncrew.com\/en\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/\" \/>\n<meta property=\"og:site_name\" content=\"JSON Crew\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-09T21:16:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress (case study)\" \/>\n<meta name=\"twitter:description\" content=\"Strona by\u0142a offline kilka dni. Pod spodem trzy niezale\u017cne rodziny z\u0142o\u015bliwego kodu + phishing kit. Jak diagnozujemy i czy\u015bcimy kompromitacj\u0119 WordPress.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"20 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/\",\"url\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/\",\"name\":\"Backdoor WordPress: 3 rodziny, cleanup w 1 dzie\u0144 | JSON Crew\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jsoncrew.com\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/wordpress-backdoor-case-study-security-20261005151233.jpg\",\"datePublished\":\"2026-10-05T15:08:03+00:00\",\"dateModified\":\"2026-10-09T21:16:48+00:00\",\"description\":\"Backdoor WordPress przez 3 lata: trzy rodziny malware, regenerator w 3 miejscach i phishing z domeny klienta. Jak usun\u0119li\u015bmy wszystko w jeden dzie\u0144.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/#primaryimage\",\"url\":\"https:\\\/\\\/jsoncrew.com\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/wordpress-backdoor-case-study-security-20261005151233.jpg\",\"contentUrl\":\"https:\\\/\\\/jsoncrew.com\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/wordpress-backdoor-case-study-security-20261005151233.jpg\",\"width\":945,\"height\":630,\"caption\":\"Obraz prowadz\u0105cy dla case study o kompromitacji instalacji WordPress przez trzy niezale\u017cne rodziny backdoor\u00f3w.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/trzy-rodziny-backdoorow-wordpress-case\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/jsoncrew.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Case Studies\",\"item\":\"https:\\\/\\\/jsoncrew.com\\\/case-studies\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/jsoncrew.com\\\/#website\",\"url\":\"https:\\\/\\\/jsoncrew.com\\\/\",\"name\":\"JSON Crew: automations, configurators, interactive meeting rooms, interactive kiosks\",\"description\":\"automations, configurators, interactive conference rooms, interactive kiosks\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/jsoncrew.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Backdoor WordPress: 3 rodziny, cleanup w 1 dzie\u0144 | JSON Crew","description":"Backdoor WordPress przez 3 lata: trzy rodziny malware, regenerator w 3 miejscach i phishing z domeny klienta. Jak usun\u0119li\u015bmy wszystko w jeden dzie\u0144.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jsoncrew.com\/en\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/","og_locale":"en_US","og_type":"article","og_title":"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress (case study)","og_description":"Strona by\u0142a offline kilka dni. Pod spodem trzy niezale\u017cne rodziny z\u0142o\u015bliwego kodu + phishing kit. Jak diagnozujemy i czy\u015bcimy kompromitacj\u0119 WordPress.","og_url":"https:\/\/jsoncrew.com\/en\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/","og_site_name":"JSON Crew","article_modified_time":"2026-10-09T21:16:48+00:00","og_image":[{"url":"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress (case study)","twitter_description":"Strona by\u0142a offline kilka dni. Pod spodem trzy niezale\u017cne rodziny z\u0142o\u015bliwego kodu + phishing kit. Jak diagnozujemy i czy\u015bcimy kompromitacj\u0119 WordPress.","twitter_image":"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg","twitter_misc":{"Est. reading time":"20 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/","url":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/","name":"Backdoor WordPress: 3 rodziny, cleanup w 1 dzie\u0144 | JSON Crew","isPartOf":{"@id":"https:\/\/jsoncrew.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/#primaryimage"},"image":{"@id":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/#primaryimage"},"thumbnailUrl":"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg","datePublished":"2026-10-05T15:08:03+00:00","dateModified":"2026-10-09T21:16:48+00:00","description":"Backdoor WordPress przez 3 lata: trzy rodziny malware, regenerator w 3 miejscach i phishing z domeny klienta. Jak usun\u0119li\u015bmy wszystko w jeden dzie\u0144.","breadcrumb":{"@id":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/#primaryimage","url":"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg","contentUrl":"https:\/\/jsoncrew.com\/wp-content\/uploads\/2026\/10\/wordpress-backdoor-case-study-security-20261005151233.jpg","width":945,"height":630,"caption":"Obraz prowadz\u0105cy dla case study o kompromitacji instalacji WordPress przez trzy niezale\u017cne rodziny backdoor\u00f3w."},{"@type":"BreadcrumbList","@id":"https:\/\/jsoncrew.com\/case-studies\/trzy-rodziny-backdoorow-wordpress-case\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/jsoncrew.com\/"},{"@type":"ListItem","position":2,"name":"Case Studies","item":"https:\/\/jsoncrew.com\/case-studies\/"},{"@type":"ListItem","position":3,"name":"Trzy rodziny backdoor\u00f3w w jednej instalacji WordPress"}]},{"@type":"WebSite","@id":"https:\/\/jsoncrew.com\/#website","url":"https:\/\/jsoncrew.com\/","name":"JSON Crew: automations, configurators, interactive meeting rooms, interactive kiosks","description":"automations, configurators, interactive conference rooms, interactive kiosks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jsoncrew.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/case_studies\/2454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/case_studies"}],"about":[{"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/types\/case_studies"}],"version-history":[{"count":6,"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/case_studies\/2454\/revisions"}],"predecessor-version":[{"id":2468,"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/case_studies\/2454\/revisions\/2468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/media\/2459"}],"wp:attachment":[{"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/media?parent=2454"}],"wp:term":[{"taxonomy":"brevo_track","embeddable":true,"href":"https:\/\/jsoncrew.com\/en\/wp-json\/wp\/v2\/brevo_track?post=2454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}